HTA-dropped Telegram_Private_Call_Session.vbs executed via WScript.Shell
Detects the execution of a specific Visual Basic script named 'Telegram_Private_Call_Session.vbs' by Windows scripting utilities (wscript.exe, cscript.exe) or the Microsoft HTML Application host (mshta.exe). This pattern is often associated with the execution of malicious scripts disguised as legitimate communication application components.
Microsoft Sentinel (KQL)

